Data flows and security pathways

This page documents the individual network flows between your environment and the Akka platform. Each flow lists the data carried, its source and destination, the connectivity used, and how it is authenticated. "Your …​" denotes a resource in your own environment.

Download the data flows as a PDF, or the full overview.

Connectivity terms used below:

  • Peering: a private network path between your environment and the Akka region.

  • Firewall, Federation Plane allowlisted: a customer-initiated outbound flow to the Federation Plane over the internet, from an allowlisted egress path.

  • Akka NAT gateway: a region-initiated egress flow. Akka can work with you to route these through your firewall instead.

  • Pre-authorized IP ranges: Federation-Plane-to-region flows over the internet. A private-connectivity option is available.

Your end users

Flow From To Connectivity Auth

End user accessing an Akka service from outside your environment

End user

Akka Region

Public (through your firewall)

Your keys, secrets, and tokens

End user accessing an Akka service from inside your environment

End user

Akka Region

Private (peering)

Your keys, secrets, and tokens

Your deployed Akka services

Flow From To Connectivity Auth

Access to your private internal systems

Your service

Your APIs

Private (peering)

Your keys, secrets, and tokens

Pushing observability metrics for your services to your observability

Akka Region

Your observability

Private (peering)

Your keys, secrets, and tokens

Your operators, admins, and developers

Flow From To Connectivity Auth

Akka CLI or console authentication initiation

CLI or console

Federation Plane

Public (firewall, Federation Plane allowlisted)

Akka authentication

OpenID authentication

Console

Your IAM

Public

OpenID

Add a region to a project

CLI

Federation Plane

Public (firewall, Federation Plane allowlisted)

Akka authenticated, valid access token

Initiate multi-region failover

CLI

Akka Region

Private (peering)

Akka authenticated, valid access token

List services and projects

CLI

Akka Region

Private (peering)

Akka authenticated, valid access token

Create a project

CLI

Federation Plane

Public (firewall, Federation Plane allowlisted)

Akka authenticated, valid access token

Add a user, role, or permission

CLI

Federation Plane

Public (firewall, Federation Plane allowlisted)

Akka authenticated, valid access token

Inspect service components in a region

CLI

Akka Region

Private (peering)

Akka authenticated, valid access token

Deploy a service: initiate deployment

CI/CD or developer

Akka Region

Private (peering)

Akka authenticated, valid access token

Deploy a service: region pulls the image

Akka Region

Your image registry

Private (peering)

Akka authenticated, valid access token

Akka SRE

Flow From To Connectivity Auth

Troubleshoot a region (cloud console or kubectl)

Your VDI, when needed

Akka Region

Private (your remote desktop)

Your cloud credentials, granted through Teleport

Akka Region

Flow From To Connectivity Auth

Region observability metadata to the Federation Plane

Akka Region

Federation Plane

Public (Akka NAT gateway)

Kubernetes RBAC and Federation Plane observability token

Region requests the public key set

Akka Region

Federation Plane

Public (Akka NAT gateway)

Internal Akka JWT authentication

Certificate expiration monitoring (can be disabled)

Akka Region

Akka SRE

Public (Akka NAT gateway)

Kubernetes RBAC

Replication to another Akka Region

Akka Region

Akka Region

Private (peering)

Mutual TLS and ACLs

Akka Federation Plane

All flows below use the bootstrap credential you create and share with Akka.

Flow From To Connectivity

Bootstrap a new Akka Region

Federation Plane

Akka Region

Public (pre-authorized IP ranges)

Install a new version of Akka into a region

Federation Plane

Akka Region

Public (pre-authorized IP ranges)

Maintain infrastructure (drift detection)

Federation Plane

Akka Region

Public (pre-authorized IP ranges)

Upgrade infrastructure (Kubernetes, database)

Federation Plane

Akka Region

Public (pre-authorized IP ranges)

Multi-region root CA management for cross-region mTLS

Federation Plane

Akka Region

Public (pre-authorized IP ranges)

Synchronize project, user, role, organization, and region metadata

Federation Plane

Akka Region

Public (pre-authorized IP ranges)

Private connectivity by cloud

Under BYOC, Akka can set up a private-connectivity option per cloud to keep region-to-internal traffic off the public internet: Transit Gateway on AWS, VPC Peering on GCP, and VNet Peering with Azure Firewall on Azure. See the BYOC on AWS, BYOC on Azure, and BYOC on GCP pages.